Skip to scanner
FileScan

FileScan

Help

01

About FileScan

FileScan is a free online service that scans uploaded files for viruses and malware using the ClamAV antivirus engine.

02

How to use

1. Drag & drop a file, click to browse, or paste with ⌘/Ctrl + V. 2. Upload and scanning start automatically. 3. See the verdict — green for clean files, red when a threat is detected. 4. Use the SHA-256 hash to get a second opinion on VirusTotal.

03

Checking emails for phishing

Save an email as an .eml file and upload it to check it against known phishing emails and for spoofed links (where the URL shown differs from the real destination). [How to save as .eml] • Gmail: open the email, click "⋮" → "Download message" • Outlook (web / new Outlook): open the email, click "…" (More actions) → "Save as" or "Download" • Apple Mail (Mac): File → Save As → choose "Raw Message Source" as the format • Thunderbird: File → Save As → File Classic Outlook for Windows saves .msg files, and phone mail apps can't save .eml, so save the email from a web or desktop mail client instead. Spoofed links impersonating major brands (Amazon, Rakuten, major banks, card issuers, carriers, delivery companies and more) are detected, but text-only links like "Log in here" and QR-code tricks can't be detected.

04

About ClamAV

ClamAV is an open-source antivirus engine capable of detecting trojans, viruses, malware, and other threats. The virus definition database is updated regularly.

05

Privacy

Uploaded files are processed in memory only and discarded once the scan completes. File contents are never shared with third parties. The SHA-256 hash is calculated inside your browser.

06

Limitations

The maximum file upload size is 10MB. All file formats are supported, but 100% detection is not guaranteed. For critical files, we recommend verifying with multiple security tools.

Threat encyclopedia

How to read detection names

Names like "Win.Trojan.Agent-1234567-0" aren't random. Here's how to read ClamAV detection names, along with the threats FileScan has actually detected, their risk level and what to do about them.

Anatomy of a detection name

Official ClamAV signatures follow the pattern Platform.Category.Name-SignatureID-Revision.

  1. WinPlatform
  2. TrojanType
  3. AgentName
  4. 1234567Signature ID
  5. 0Revision
Platform
The targeted environment or file format: Win for Windows, Doc for Word documents, Pdf for PDF, and so on.
Type
The malware category, such as Trojan or Ransomware.
Name (family)
The name of a known malware family such as Emotet. Agent or Generic are catch-all names.
Signature ID
The identifier within the ClamAV database.
Revision
The signature's revision number.

Special names

PUA.
Potentially Unwanted Application — tools or adware that aren't necessarily malicious.
Heuristics.
A warning based on file traits rather than a signature (encryption, macros, sensitive data, etc.). Not necessarily a virus.
Eicar-Test-Signature
A harmless test file used to check that antivirus software works.

Threats detected on FileScan

Test signatures (such as EICAR) are excluded from scan statistics like the infection rate.

RankDetection nameTypeRiskDetections
01Eicar-Test-SignatureTestTest file (EICAR)601 hits
02Heuristics.Structured.CreditCardNumberCredit card numbers4 hits
03Txt.Backdoor.MetasploitPayload-9874938-0Backdoor1 hit
04Heuristics.Structured.SSNUS Social Security numbers1 hit
05Heuristics.Phishing.Email.SpoofedDomainSuspected phishing1 hit